Candidate: CVE-2016-4414 PublicDate: 2016-06-13 19:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4414 https://github.com/quassel/quassel/blob/f64ac93/src/core/coreauthhandler.cpp#L100 http://www.openwall.com/lists/oss-security/2016/04/30/2 Description: The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data. Ubuntu-Description: Notes: sbeattie> affect quassel 0.10 through 0.12.3) Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_quassel: upstream: https://github.com/quassel/quassel/commit/e67887343c433cc35bc26ad6a9392588f427e746 upstream_quassel: released (1:0.12.4-2) precise_quassel: not-affected (0.10.x and later only) precise/esm_quassel: DNE (precise was not-affected [0.10.x and later only]) trusty_quassel: ignored (reached end-of-life) trusty/esm_quassel: DNE (trusty was needed) vivid/stable-phone-overlay_quassel: DNE vivid/ubuntu-core_quassel: DNE wily_quassel: ignored (reached end-of-life) xenial_quassel: ignored (end of standard support, was needed) yakkety_quassel: ignored (reached end-of-life) zesty_quassel: ignored (reached end-of-life) artful_quassel: not-affected (1:0.12.4-2ubuntu2) bionic_quassel: not-affected (1:0.12.4-2ubuntu2) cosmic_quassel: not-affected (1:0.12.4-2ubuntu2) disco_quassel: not-affected (1:0.12.4-2ubuntu2) eoan_quassel: not-affected (1:0.12.4-2ubuntu2) focal_quassel: not-affected (1:0.12.4-2ubuntu2) groovy_quassel: not-affected (1:0.12.4-2ubuntu2) hirsute_quassel: not-affected (1:0.12.4-2ubuntu2) impish_quassel: not-affected (1:0.12.4-2ubuntu2) jammy_quassel: not-affected (1:0.12.4-2ubuntu2) devel_quassel: not-affected (1:0.12.4-2ubuntu2)